Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

111–120 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#111
post #49

Earlier quoted context omitted.

I bet the tool was bought from a supplier but Signal team can't disclose it because source protection.

With all the recent BLM protests going on, I wouldn't be surprised if it was acquired by an activist, even an activist who works in the police force!

This is irresponsible and inflammatory. Has nothing to do with the discussion. Please stop.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#112
post #6

So I wonder, why disclose this? This will just prompt Cellebrite to improve its security process and sandbox the entire tool. If they wanted to destroy the credibility of the tool, using the vulnerabilities to silently tamper with the collected data or even leaking it online would be a much better option and hit them without any warning, not only jeopardizing those cases but forever casting doubt on not just Cellebri…

Probably disclosure is the best option.

Silently tamper with the data might cross a legal line. doing this might put at risk current or past cases where there is a legitimate reason to use this sort of tool.

Privacy can be hard. While i 100% defend everybody has the right to privacy, i can also see the need for the capability to break it. Maybe the answer for this is a very tight regulation around the uses of this kind of hardware/software, but that regulation would have to keep up with the pace of technology

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#113

I don't understand the seeming incongruity between these two statements: On the one hand: > One way to think about Cellebrite’s products is that if someone is physically holding your unlocked device in their hands, they could open whatever apps they would like and take screenshots of everything in them to save and go over later. Cellebrite essentially automates that process for someone holding your device in their ha…

they could use vulnerabilities to extract more data. probably it's common to do some obfuscation of data which celebrite might have reverse engineered.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#114

> In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software. I wish I could see those files in action...

signal wants to pick a fight with a grey company that gets money for cracking apps? not a good idea

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#115

i find it remarkably unbelievable someone would put a cellebrite bag in the back of a truck given the price alone.. and the timing too. sure

"fell off the back of a truck" is an idiom [1]. It's not meant literally. [1] https://www.phrases.org.uk/meanings/fell-off-the-back-of-a-t...

oh ok thats a new one for me obviously, but the street photo got me. lol

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#116
post #99

Earlier quoted context omitted.

Any court case where Cellebrite's tools have been used are now in jeopardy since the defence can just say that they were hacked by someone else. There's now reasonable doubt that Cellebrite can't be trusted. This damages their reputation with governments too.

This is unlikely to be the case, despite the vulnerabilities that are described. The process of e-discovery is rife with risks of this sort. When you forensically collect data from a random set of devices from a party that may or may not have porn, HIPAA, GDPR, sample viruses, malware, who know what all. The short version of it even if the inhaling of this data crashes the device, there are mitigations and protection…

The vulnerability claimed here doesn't necessarily crash the computer running the software. It runs arbitrary code, and said code is able to modify the data Cellebrite extracts. It is not clear whether it is possible to detect whether data collected in the past is compromised.

There may be mitigations, but without knowing the full details of the exploit, it sounds a lot like reasonable doubt to me. A good lawyer would spin it exactly that way, putting any cases without sufficient corroborating evidence in jeopardy.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#117

i find it remarkably unbelievable someone would put a cellebrite bag in the back of a truck given the price alone.. and the timing too. sure

“Fell off the back of a truck” is slang for “obtained through illicit means.” It comes from the excuse that criminals used to give when caught with stolen property: I didn’t steal it, it just fell off a truck.

thank you for clarifying, english is not my main language and that was taken at face value. The going on a walk and picture was too good

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#118

Earlier quoted context omitted.

Maybe the one thing worse than boasting that you're putting malware in your product is boasting about it and not doing it.

Is it malware if users desire for their devices to be resistant to surveillance tools?

goodware ??

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#119
post #64

A reminder that you can pair lock your iPhone to prevent analysis by Cellebrite or similar tools: https://arkadiyt.com/2019/10/07/pair-locking-your-iphone-wit...

All of these are based on the assumption that the attacker has physical access to the unlocked phone, right?

I'm trying to understand the risk profile here.

I guess I see the value for, e.g., a border crossing, where they can inconvenience you and ask you to unlock your phone, but instead of flicking through your messages briefly, they authorize a pairing and quickly backup your entire disk content. You expected a quick perusal by a human, but unknowingly gave them a lot more. If you've blocked pairing, they can't get nearly as much data as quickly.

But if you're being investigated for committing a crime, everything we think we know about device unlocking is still true, right? They'd need me to unlock it before it'd trust a new device to pair to, and they'd need a court order to get me to unlock it for them. Five quick taps of the power button and biometric unlocks are off--now they need my passcode.

Perhaps there's still value, even in that case, in that if I were compelled via court order to give my passcode, they still can't quickly / easily dump the disk contents from a device pairing. Although I imagine if you have the passcode there's probably many other ways of accomplishing the same result.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#120
Wow, that video made my day. This bit is key:

> "For example, by including a specially formatted but otherwise innocuous file in an app on a device that is then scanned by Cellebrite, it’s possible to execute code that modifies not just the Cellebrite report being created in that scan, but also all previous and future generated Cellebrite reports from all previously scanned devices and all future scanned devices in any arbitrary way (inserting or removing text, email, photos, contacts, files, or any other data), with no detectable timestamp changes or checksum failures. This could even be done at random, and would seriously call the data integrity of Cellebrite’s reports into question."

They've may have just got a lot evidence collected using Cellebrite from phones with (or without) Signal installed on them thrown out of court.

I don't recall the details, but there was an absolute unsubstantiated speculative and surely fictional rumor of at least one entirely theoretical zero-day non-gif formatted image file that exploited a similar class of vulnerability in what was probably not a market leading tool used tangentially for the same purposes, floating around well over a decade ago as well.

I for one am very glad that these hypothetical issues have almost surely been fixed.

Post reply on HN